{"id":"DEBIAN-CVE-2007-4408","details":"ircu 2.10.12.05 and earlier ignores timestamps in bounces, which allows remote attackers to take over a channel during a netjoin by causing a bounce while a server with an older version of the channel is linking.","modified":"2026-09-01T20:02:47.950616645Z","published":"2007-08-18T21:17:00Z","upstream":["CVE-2007-4408"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2007-4408"}],"affected":[{"package":{"name":"ircd-ircu","ecosystem":"Debian:12","purl":"pkg:deb/debian/ircd-ircu?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.10.12.10.dfsg1-1"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-4408.json"}},{"package":{"name":"ircd-ircu","ecosystem":"Debian:13","purl":"pkg:deb/debian/ircd-ircu?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.10.12.10.dfsg1-1"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-4408.json"}},{"package":{"name":"ircd-ircu","ecosystem":"Debian:14","purl":"pkg:deb/debian/ircd-ircu?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.10.12.10.dfsg1-1"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-4408.json"}}],"schema_version":"1.9.0"}